CloseProcesses: CreateRestorePoint: ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} => No File GroupPolicy: Restriction - Chrome <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = SearchScopes: HKU\.DEFAULT -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = SearchScopes: HKU\S-1-5-21-270719932-3992731346-3884529842-1001 -> DefaultScope {1B2907BB-FF5D-4224-9AA7-EBE89AAF0B7B} URL = SearchScopes: HKU\S-1-5-21-270719932-3992731346-3884529842-1001 -> {3885C94D-38F8-4DFD-B31A-59C9811C556E} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1 SearchScopes: HKU\S-1-5-21-270719932-3992731346-3884529842-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = SearchScopes: HKU\S-1-5-21-270719932-3992731346-3884529842-1005-{637FE20B-9A5B-4F51-B1BE-D10045625B40}-0 -> {E1339969-795B-413D-B352-DEFBFAF1F910} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US105D20121011&p={searchTerms} BHO: No Name -> {27B4851A-3207-45A2-B947-BE8AFE6163AB} -> No File BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File S2 HomeNetSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 McBootDelayStartSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 McNaiAnn; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 mcpltsvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 McProxy; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] S2 MSK80Service; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X] U3 idsvc; no ImagePath S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [X] S3 PCDSRVC{1E208CE0-FB7451FF-06020200}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [X] C:\Users\jcott\AppData\Local\Temp\dxwebsetup.exe C:\Users\jcott\AppData\Local\Temp\vsredistsetup.exe C:\Users\steven\AppData\Local\Temp\DefaultPack.EXE C:\Users\steven\AppData\Local\Temp\jre-8u71-windows-au.exe C:\Users\steven\AppData\Local\Temp\libeay32.dll C:\Users\steven\AppData\Local\Temp\msvcr120.dll C:\Users\steven\AppData\Local\Temp\sqlite3.dll Task: {10712C85-C199-4245-BDA4-57827D08ED73} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION Task: {185C5E45-F4E5-4B37-8AD1-80B821E94869} - System32\Tasks\REGUtilities Task => C:\Program Files (x86)\REGUtilities\REGUtilities.exe <==== ATTENTION Task: {2824C10D-5D55-442F-A7F1-38A73B4FA8BC} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION Task: {2C794F92-9DA9-4901-8EF9-F1D3D8DE19A6} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION Task: {2EA26D21-43EB-401B-B342-BD0B5474C7B6} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION Task: {4DA06947-9CC4-4253-A618-7DFA60920D10} - \PCDEventLauncher -> No File <==== ATTENTION Task: {5320EC7B-F649-4898-B2AB-11D0C3C38103} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION Task: {6C87747A-6F96-478E-84DF-93E48B5570D0} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION Task: {81B1BA89-20A9-45AC-A115-B10975A07D11} - \SystemToolsDailyTest -> No File <==== ATTENTION Task: {86B2785F-EC39-4CC5-A41E-225A35F95341} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION Task: {8A111D0B-A9EF-44C1-BEDB-DEABDC0D3259} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION Task: {8C4BBBA9-5FEF-4086-95F6-4CCF0795788D} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION Task: {ADD60308-5A0E-4B71-9FD4-1B1A1E40E148} - \{0E047847-790E-0A0D-7A11-057E0F08117E} -> No File <==== ATTENTION Task: {DB08B41F-4E46-49E6-A13D-13A54E5F8EBB} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION Task: {E63652F9-3BCA-442D-84C1-AE99E52C9121} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION Task: {FA7C56CA-5C0F-4EC8-A396-81EC1C8D4C02} - \PCDoctorBackgroundMonitorTask -> No File <==== ATTENTION Task: {FAA637C8-D1D2-47DC-9995-6EFFF10B462C} - System32\Tasks\{C6DB9F2D-C049-06A3-8C29-090994E9A96F} => Regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\6e11d460\25284cc3.dll" <==== ATTENTION Task: C:\WINDOWS\Tasks\REGUtilities Task.job => C:\Program Files (x86)\REGUtilities\REGUtilities.exe-t C:\Program Files (x86)\REGUtilities\REGUtilities.exe <==== ATTENTION C:\Program Files (x86)\REGUtilities\ ShortcutWithArgument: C:\Users\steven\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Chrome (2).lnk -> C:\Users\steven\AppData\Local\Chrome\Application\chrome.exe (The Chromium Authors) -> --extra-search-query-params="brocodeid=769&publisher=QuickObrw&dpid=QuickObrw&co=US&userid=d01b1752-774b-fb67-745e-8ea306d0161d&installdate=01/01/2014&searchtype=cd" "hxxp://feed.snapdo.com/?searchtype=cn&brocodeid=769&publisher=QuickObrw&dpid=QuickObrw&co=US HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service" CMD: bitsadmin /reset /allusers CMD: netsh winsock reset catalog CMD: ipconfig /flushdns RemoveProxy: hosts: Emptytemp: